Lucene search

K
f5F5F5:K16441
HistoryApr 15, 2015 - 12:00 a.m.

K16441 : MIT Kerberos 5 vulnerability CVE-2014-9423

2015-04-1500:00:00
my.f5.com
31

AI Score

5.6

Confidence

Low

EPSS

0.008

Percentile

82.2%

Security Advisory Description

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field. (CVE-2014-9423)
Impact
There is no impact; F5 products are not affected by this vulnerability.